skills/nicepkg/ai-workflow/shioaji/Gen Agent Trust Hub

shioaji

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted financial data from external market feeds.
  • Ingestion points: Market data ticks and bid/ask quotes are ingested via STREAMING.md, MARKET_DATA.md, and historical queries in ADVANCED.md.
  • Boundary markers: There are no specific instructions or delimiters to isolate or ignore potentially malicious instructions embedded within the market data streams.
  • Capability inventory: The skill enables the agent to place financial orders (api.place_order), modify trades, and interact with local project files via uv.
  • Sanitization: The ingested market data is processed without visible validation or sanitization before being potentially incorporated into agent decision-making processes.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download and installation of necessary development tools and libraries.
  • Downloads the uv installation script from Astral's official domain to manage the Python environment.
  • Recommends installing the shioaji API library from standard package registries and Docker Hub.
  • Fetches official demo code from the Sinotrade GitHub repository.
  • [COMMAND_EXECUTION]: The skill uses shell commands for environment configuration and script execution.
  • Executes piped installation scripts for the uv tool.
  • Uses uv run and pip install to set up dependencies and execute trading workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:05 AM
Security Audit — agent-trust-hub — shioaji